# About the Filebeat type: docker

**URL:** <https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [January 6, 2020, 9:54am UTC](https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868 "2020-01-06T09:54:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BoboZheng](https://avatars.discourse-cdn.com/v4/letter/b/9de0a6/32.png) [@BoboZheng](https://discuss.elastic.co/u/BoboZheng)\
**Post date:** [January 6, 2020, 9:54am UTC](https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868/1 "2020-01-06T09:54:41Z")

</div>

## Hi, I have a question about filebeat.yml. I want to match the specified pod\_name, but processors.add\_kubernetes\_metadata only match namespace. this is my setting:

## metadata: name: filebeat-inputs namespace: elk data: kubernetes.yml: | - type: docker combine\_partial: true fields: log\_topics: wiz-pre containers: path: "/var/lib/docker/containers" stream: "all" ids: "\*" multiline.pattern: '^\d{4}-' multiline.negate: true multiline.match: after exclude\_lines: ['Completed', 'Triggering'] tail\_files: true processors: - add\_kubernetes\_metadata: in\_cluster: true namespace: default

if I have a pod which name is testpod\_xxxx (kind: Deployment), how can I only output this pod logs?

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [January 9, 2020, 8:17pm UTC](https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868/2 "2020-01-09T20:17:19Z")

</div>

It sounds like you aren't trying to limit the scope of `add_kubernetes_metadata` so much as to only run it on a certain pod. That kind of change should probably go in your kubernetes config, e.g. using `spec.selector` to limit the daemonset configuration to a particular pod. `namespace` is to control which environment the `add_kubernetes_metadata` processor queries, but the processor has no control over which pod it's running on, which is why there isn't an analogous setting for `pod`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2020, 8:17pm UTC](https://discuss.elastic.co/t/about-the-filebeat-type-docker/213868/3 "2020-02-06T20:17:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
